Could you provide me with a little guidance please.
I have two new FortiGate 300D devices, running firmware v5.4. The two devices are part of a HA cluster.
I also have a FortiAnalyzer running firmware v5.4.1.
What process do I following to add the FortiGate devices to the FortiAnalyzer.
1. Add each of the FortiGate devices individually, to the FortiAnalyzer by specifying their management interface IP addresses?
OR
1. Add the FortiGate device, that is acting as the master in the HA cluster, specifying the cluster interface IP address
2. Edit the device and check "HA Cluster"
3. Add the second device
OR do i do something else.
Many thanks.
You must click the "HA cluster" option in the Add Device wizard. Then you must enter all the SN of the devices in the cluster. Have in mind that all cluster members generate logs, but only the primary device sends the logs to the FAZ. All the other cluster members send their logs to the primary.
Okay, thanks. When adding the primary device to the FortiAnalyzer, do I specify the IP address of the cluster interface rather than the IP address of the management interface
It is a good practice to reserve a management port for each Fortigate, so that you can manage each cluster member separately. Having said that, you may use any other IP address of a cluster interface which is reachable by the FAZ. Some people prefer using a loopback address for that.
Apologies, I think you may have misunderstood.
I have a management interface configured on each of the devices, for the reasons you specify above.
However, when adding the device to the FortiAnalyzer, I must specify one of the IP addresses that is common to both devices. For example the IP address of port1, which will be the same regardless of which device is in control of the cluster. Is this correct?
As I said, you may use any interfaces's IP address that suits you. The only requirement is that the FAZ must have access to this IP address.
Would I be correct in thinking that if I specified the management IP address of the primary device and a failover occurred, the FortiAnalyzer would no longer receive alerts because the IP address is no longer in use?
Hi,
If I remember correctly the IP addresss does not matter. The serial number has to be configured on the FAZ and set it as a HA cluster.
What if someone will have an office and the IP address is assigned dynamically to Fortigate. The addresss changes - it should logging in this case also.
Is it a problem to arrange a 15min maintenance window and check what happens?
AtiT
I just made some test (FAZ 5.2.8) and I added the device with the IP address 1.1.1.1 to the FAZ.
After I received the first log the IP address changed to the WAN IP.
I think it should work.
AtiT
Yes, this is correct in the case that the other cluster members have different IP address in their management port.
In FortiGates with two management ports, you may use one port for the cluster management and keep the other for management access to each FortiGate individually.
 
					
				
				
			
		
| User | Count | 
|---|---|
| 2677 | |
| 1412 | |
| 810 | |
| 703 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.